EPIC calls for further Passport curbs

The Electronic Privacy Information Center (EPIC) has lobbied the US Federal Trade Commission (FTC) to take further action to...

The Electronic Privacy Information Center (EPIC) has lobbied the US Federal Trade Commission (FTC) to take further action to limit Microsoft's Passport online authentication service, amid complaints of misrepresentation and slack security.

Civil liberties group EPIC has sent a letter to the FTC saying that while the consent agreement the commission reached with Microsoft last month would "go far in improving security and privacy" of users' information, it did not go far enough.

The group claims that the single sign-on authentication system has experienced security breaches since the consent agreement was reached and, despite user resistance to online authentication tools, that Microsoft has not been forthright in communicating how it is expanding the service.

The FTC began investigating concerns over Passport's security and privacy over a year ago, following a complaint filed by EPIC. The commission finally reached a consent agreement with the software maker last month, ordering Microsoft to cease misrepresenting the information collected by the service, and bolster its security program.

While EPIC applauded the agreement, it urged the FTC this week to further regulate Passport by requiring greater transparency, allowing users access to their entire Passport profile and limiting the functions of the service to guarantee greater security.

EPIC said that because Passport serves as a single key to users' online information, the damage caused by a security breach could be substantial. The group suggested that the FTC limit Passport's functions in order to reduce this risk.

The group also suggests that biannual security assessments mandated by the consent agreement should be made public, and that users should be able to easily view and correct their profiles.

While EPIC originally voiced its concerns about Passport's security and privacy, the group said that emerging online authentication services should also be scrutinised.

America Online has launched a "Screen Name Service" which tracks users' personal information while Liberty Alliance has also developed "Project Liberty," an online identification and authentication system, EPIC said. The group asks that both be examined for their security and privacy features, saying they pose the same hazards as Passport does.

While no one from Microsoft was immediately available to comment on EPIC's latest request, the software maker has in the past said that it plans to continue improving Passport's security features.

The European Commission is also currently evaluating Passport's security.

Read more on IT risk management